CVE-2026-48210

5.7 MEDIUM
Published: May 31, 2026 Modified: June 15, 2026
View on NVD

Description

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the β€œIs visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend This issue affects OTRS 2026.3.1

AI Explanation

### 1. Plain-Language Summary (2-3 sentences): In OTRS 2026.3.1, a default setting forces all forwarded ticket articles to be visible to external customers, and users cannot turn this visibility off. This accidentally exposes internal ticket details (like notes or attachments) to external users through the External Frontend, even when they shouldn't see them. ### 2. Who is Affected: * **Product:** OTRS (Open-source Ticket Request System) * **Version:** Specifically **OTRS 2026.3.1**. Earlier or later versions are not mentioned as affected. ### 3. What an Attacker Could Do: An attacker with access to the OTRS **External Frontend** could view internal information (e.g., agent notes, sensitive attachments, internal communications) within tickets that were forwarded, which should have remained private. This unauthorized exposure could lead to information disclosure breaches. ### 4. Recommended Remediation Steps: 1. **Verify Exposure:** Immediately check if forwarded articles in OTRS 2026.3.1 are visible in the External Frontend despite agent attempts to hide them. 2. **Contact Vendor:** Reach out to the OTRS vendor (OTRS AG) for an official patch or configuration fix. 3. **Apply Patch/Upgrade:** Install the vendor-provided patch as soon as it becomes available. If a fixed version is released (e.g., 2026.3.2+), upgrade to it. 4. **Temporary Workaround (If Possible):** Until a patch is available, **restrict access** to the External Frontend or **disable ticket forwarding** functionality entirely if business

Generated: 2026-06-01 01:03

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://otrs.com/release-notes/otrs-security-advisory-2026-09/
Source: security@otrs.com
Vendor Advisory Mitigation

1 reference(s) from NVD

Quick Stats

CVSS v3 Score
5.7 / 10.0
EPSS (Exploit Probability)
0.2%
16th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

otrs